<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:05:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-53171 — ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-53171</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit&lt;/p&gt;
&lt;p&gt;After an insertion in TNC, the tree might split and cause a node to
change its `znode-&amp;gt;parent`. A further deletion of other nodes in the
tree (which also could free the nodes), the aforementioned node&amp;#39;s
`znode-&amp;gt;cparent` could still point to a freed node. This
`znode-&amp;gt;cparent` may not be updated when getting nodes to commit in
`ubifs_tnc_start_commit()`. This could then trigger a use-after-free
when accessing the `znode-&amp;gt;cparent` in `write_index()` in
`ubifs_tnc_end_commit()`.&lt;/p&gt;
&lt;p&gt;This can be triggered by running&lt;/p&gt;
&lt;p&gt;rm -f /etc/test-file.bin
  dd if=/dev/urandom of=/etc/test-file.bin bs=1M count=60 conv=fsync&lt;/p&gt;
&lt;p&gt;in a loop, and with `CONFIG_UBIFS_FS_AUTHENTICATION`. KASAN then
reports:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in ubifs_tnc_end_commit+0xa5c/0x1950
  Write of size 32 at addr ffffff800a3af86c by task ubifs_bgt0_20/153&lt;/p&gt;
&lt;p&gt;Call trace:
   dump_backtrace+0x0/0x340
   show_stack+0x18/0x24
   dump_stack_lvl+0x9c/0xbc
   print_address_description.constprop.0+0x74/0x2b0
   kasan_report+0x1d8/0x1f0
   kasan_check_range+0xf8/0x1a0
   memcpy+0x84/0xf4
   ubifs_tnc_end_commit+0xa5c/0x1950
   do_commit+0x4e0/0x1340
   ubifs_bg_thread+0x234/0x2e0
   kthread+0x36c/0x410
   ret_from_fork+0x10/0x20&lt;/p&gt;
&lt;p&gt;Allocated by task 401:
   kasan_save_stack+0x38/0x70
   __kasan_kmalloc+0x8c/0xd0
   __kmalloc+0x34c/0x5bc
   tnc_insert+0x140/0x16a4
   ubifs_tnc_add+0x370/0x52c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit&lt;/p&gt;
&lt;p&gt;After an insertion in TNC, the tree might split and cause a node to
change its `znode-&amp;gt;parent`. A further deletion of other nodes in the
tree (which also could free the nodes), the aforementioned node&amp;#39;s
`znode-&amp;gt;cparent` could still point to a freed node. This
`znode-&amp;gt;cparent` may not be updated when getting nodes to commit in
`ubifs_tnc_start_commit()`. This could then trigger a use-after-free
when accessing the `znode-&amp;gt;cparent` in `write_index()` in
`ubifs_tnc_end_commit()`.&lt;/p&gt;
&lt;p&gt;This can be triggered by running&lt;/p&gt;
&lt;p&gt;rm -f /etc/test-file.bin
  dd if=/dev/urandom of=/etc/test-file.bin bs=1M count=60 conv=fsync&lt;/p&gt;
&lt;p&gt;in a loop, and with `CONFIG_UBIFS_FS_AUTHENTICATION`. KASAN then
reports:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in ubifs_tnc_end_commit+0xa5c/0x1950
  Write of size 32 at addr ffffff800a3af86c by task ubifs_bgt0_20/153&lt;/p&gt;
&lt;p&gt;Call trace:
   dump_backtrace+0x0/0x340
   show_stack+0x18/0x24
   dump_stack_lvl+0x9c/0xbc
   print_address_description.constprop.0+0x74/0x2b0
   kasan_report+0x1d8/0x1f0
   kasan_check_range+0xf8/0x1a0
   memcpy+0x84/0xf4
   ubifs_tnc_end_commit+0xa5c/0x1950
   do_commit+0x4e0/0x1340
   ubifs_bg_thread+0x234/0x2e0
   kthread+0x36c/0x410
   ret_from_fork+0x10/0x20&lt;/p&gt;
&lt;p&gt;Allocated by task 401:
   kasan_save_stack+0x38/0x70
   __kasan_kmalloc+0x8c/0xd0
   __kmalloc+0x34c/0x5bc
   tnc_insert+0x140/0x16a4
   ubifs_tnc_add+0x370/0x52c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-53171</guid>
    </item>
  </channel>
</rss>
